CVE-2005-3364

Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:platinum:dboardgear:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:01

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=113017087231116&w=2 - () http://marc.info/?l=bugtraq&m=113017087231116&w=2 -
References () http://securityreason.com/securityalert/109 - () http://securityreason.com/securityalert/109 -
References () http://securitytracker.com/id?1015095 - Exploit () http://securitytracker.com/id?1015095 - Exploit
References () http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-10/0298.html - Exploit () http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2005-10/0298.html - Exploit
References () http://www.osvdb.org/20442 - () http://www.osvdb.org/20442 -
References () http://www.osvdb.org/20443 - () http://www.osvdb.org/20443 -
References () http://www.securityfocus.com/bid/15174 - Vendor Advisory () http://www.securityfocus.com/bid/15174 - Vendor Advisory
References () http://www.securityfocus.com/bid/15194 - () http://www.securityfocus.com/bid/15194 -

Information

Published : 2005-10-30 14:34

Updated : 2024-11-21 00:01


NVD link : CVE-2005-3364

Mitre link : CVE-2005-3364

CVE.ORG link : CVE-2005-3364


JSON object : View

Products Affected

platinum

  • dboardgear